CVE-2023-21608: high-severity vulnerability in Adobe Acrobat Reader
Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe Acrobat Reader has a flaw where it tries to use data that has already been freed from memory when handling PDF forms. An attacker can exploit this by sending a malicious PDF file that, when opened, allows them to run code on the victim's computer.
Use-after-free vulnerability in Adobe Acrobat Reader's resetForm function allows remote code execution with user context privileges. Attack vector requires user interaction (opening a malicious PDF file); no authentication or special privileges are needed. Affected versions include 22.003.20282 and earlier, 22.003.20281 and earlier, and 20.005.30418 and earlier.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.